[PULL 15/43] hw/arm/ax3000-soc: fix heap overflow from missing class_size
Peter Maydell <[email protected]>
| Newsgroups | org.nongnu.qemu-devel |
|---|---|
| Message-ID | <[email protected]> |
From: Doug Cook <[email protected]> TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and ax3000_class_init() writes to it: Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc); sc->num_cpus = AX3000_NUM_CPUS; but its TypeInfo omits .class_size, so type_initialize() only allocates class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass). The store to sc->num_cpus therefore writes 4 bytes of the value 4 just past the end of the class allocation, corrupting whatever heap block follows it. Fix by setting class_size. Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197 Signed-off-by: Doug Cook <[email protected]> Message-id: LVXPR21MB70090B04FF7397B0F2A201C8ADA72@LVXPR21MB7009.namprd21.prod.outlook.com Reviewed-by: Peter Maydell <[email protected]> Signed-off-by: Peter Maydell <[email protected]> --- hw/arm/ax3000-soc.c | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/arm/ax3000-soc.c b/hw/arm/ax3000-soc.c index 71e31c6fb46..ebe174fb978 100644 --- a/hw/arm/ax3000-soc.c +++ b/hw/arm/ax3000-soc.c @@ -236,6 +236,7 @@ static const TypeInfo axiado_soc_types[] = { .instance_size = sizeof(Ax3000SoCState), .instance_init = ax3000_init, .class_init = ax3000_class_init, + .class_size = sizeof(Ax3000SoCClass), } }; -- 2.43.0